Hub
Virtualization

VMware vCenter vpxd Events

VMware vCenter Server 8.0 vpxd events forwarded over RFC 5424 syslog and indexed by the Elastic VMware vSphere integration (vsphere.log): API logins and logouts, failed SSO logins, VM power and reconfiguration, and permission changes, with the native syslog line in event.original. About 8,100 records a day from one vCenter: four service accounts around the clock and eight staff accounts on a UTC working day. Recurring episodes show three to five failed SSO logins for one administrator, then that administrator's login and an Admin permission grant.

Quick Start

uv tool install eventum-generator
git clone https://github.com/eventum-generator/content-packs.git
cd content-packs
eventum generate \
  --path generators/virtualization-vmware/generator.yml \
  --id vmware \
  --live-mode true

Event Types

Event IDDescriptionFrequencyCategory
vim.event.UserLoginSessionEventAPI session opened49.26% of recordsauthentication
vim.event.UserLogoutSessionEventSession closed, with login time and number of API calls49.24% of recordsauthentication
vim.event.VmPoweredOffEventVM powered off0.55% of recordshost
vim.event.VmPoweredOnEventThe same VM powered on again0.55% of recordshost
vim.event.VmReconfiguredEventnumCPU or memoryMB changed while the VM is off0.17% of recordsconfiguration
vim.event.EventExFailed SSO login: wrong password for a staff account0.11% of recordsauthentication
vim.event.PermissionAddedEventTemporary permission created0.08% of recordsiam
vim.event.PermissionRemovedEventExpired permission removed0.04% of recordsiam

Realism Features

  • One vCenter manages one datacenter with twelve VMs on three ESXi hosts. Four service accounts log in and out every few seconds to minutes: a monitoring poller about 2,300 times a day, a metrics collector about 970, an orchestration account about 390 and a backup account about 200. Eight staff accounts (four administrators, two helpdesk operators, two developers) log in about 3-17 times a day each, administrators most.
  • About 8,100 records a day, ±3% from day to day: about 7,900 from service accounts at a flat rate and about 220 from staff, 90% of them at 07-17 UTC, 6% at 06-07 and 17-19 and 4% at night. The hour curve repeats every day, with no weekly cycle.
  • Staff sessions last a median 10-12 minutes (90th percentile about 30); monitoring poller sessions a median 14 s, metrics collector sessions about 2 minutes, backup sessions about 10 minutes. Records of one session are seconds to minutes apart rather than milliseconds, and logout records carry the login time, duration and number of API calls.
  • 7% of staff sessions start with one to five wrong passwords, each extra failure rarer than the previous one, and 12% of those end without a login; service accounts never fail. Runs of three or more failures before a login occur a few times a week in ordinary traffic.
  • Administrators and operators power-cycle VMs or change numCPU or memoryMB one step while the VM is off, developers power-cycle test and batch VMs, and every VM powered off is powered on again in the same session. About six temporary grants a day (one or two of them Admin) give five internal role names to eight principals on the datacenter, two clusters, three folders or two VMs; each is removed after a median 36 hours (2 hours to 14 days), with at most one permission per principal and entity.
  • Logins and logouts carry the user, source address and user agent fields the Elastic vSphere pipeline derives, failed SSO logins user.name and source.ip. For VM and permission events the pipeline only splits the syslog envelope, so the acting account, VM and principal stay in message and event.original; their wording follows the vCenter event catalog rather than a recorded vCenter log, and reconfiguration is written on one line with CPU and memory changes only.
  • Only eight vpxd event classes are present; tasks, alarms, host and cluster events are not. Every account uses one fixed address and user agent Go-http-client/1.1, and the collector fields describe a synthetic Elastic Agent. With anomalies on, runs of three or more failures before a login are about one a day more frequent and Admin grants rise to two or three a day.

Sample Output

{
  "@timestamp": "2026-09-01T11:00:13.646Z",
  "agent": {
    "ephemeral_id": "c4a1df82-7a9c-4a3e-8546-6d7cc04538e6",
    "id": "5096d7cc-1e4b-4959-abea-7355be2913a7",
    "name": "log-collector-01.lab.example",
    "type": "filebeat",
    "version": "8.17.0"
  },
  "client": {
    "ip": "10.40.3.22"
  },
  "data_stream": {
    "dataset": "vsphere.log",
    "namespace": "default",
    "type": "logs"
  },
  "ecs": {
    "version": "8.11.0"
  },
  "elastic_agent": {
    "id": "5096d7cc-1e4b-4959-abea-7355be2913a7",
    "snapshot": false,
    "version": "8.17.0"
  },
  "event": {
    "agent_id_status": "verified",
    "category": [
      "authentication"
    ],
    "dataset": "vsphere.log",
    "id": "674988",
    "ingested": "2026-09-01T11:00:14Z",
    "kind": "event",
    "original": "\u003c14\u003e1 2026-09-01T11:00:13.646579+00:00 vcsa01.lab.example vpxd 36683 - -  Event [674988] [1-1] [2026-09-01T11:00:13.646479Z] [vim.event.EventEx] [info] [ops.petrova] [] [674988] [Failed login ops.petrova from 10.40.3.22 at 09/01/2026 11:00:13 GMT in SSO]",
    "outcome": "failure",
    "timezone": "+00:00",
    "type": [
      "info"
    ]
  },
  "host": {
    "architecture": "x86_64",
    "containerized": false,
    "hostname": "log-collector-01.lab.example",
    "id": "3f0b6c1e2d9a4c7f8e5b1a2d3c4e5f60",
    "ip": [
      "10.40.0.50"
    ],
    "mac": [
      "00-50-56-A1-7B-10"
    ],
    "name": "vcsa01.lab.example",
    "os": {
      "codename": "jammy",
      "family": "debian",
      "kernel": "5.15.0-122-generic",
      "name": "Ubuntu",
      "platform": "ubuntu",
      "type": "linux",
      "version": "22.04.5 LTS (Jammy Jellyfish)"
    }
  },
  "input": {
    "type": "udp"
  },
  "log": {
    "level": "info",
    "logger": "vim.event.EventEx",
    "source": {
      "address": "10.40.0.10:59236"
    },
    "syslog": {
      "facility": {
        "code": 1,
        "name": "User"
      },
      "priority": 14,
      "severity": {
        "code": 6,
        "name": "Informational"
      }
    }
  },
  "message": "[ops.petrova] [] [674988] [Failed login ops.petrova from 10.40.3.22 at 09/01/2026 11:00:13 GMT in SSO]",
  "process": {
    "name": "vpxd",
    "pid": 36683
  },
  "related": {
    "ip": [
      "10.40.3.22"
    ]
  },
  "source": {
    "ip": "10.40.3.22"
  },
  "tags": [
    "preserve_original_event",
    "vmware-sphere"
  ],
  "user": {
    "name": "ops.petrova"
  }
}

Parameters

ParameterDefaultDescription
anomaly_modetrueEmit recurring anomaly episodes; false gives background only
anomaly_interval_hours24Interval between episodes in event time, 6 to 8,760 hours
vcenter_hostvcsa01.lab.examplevCenter hostname in the syslog header (host.name)
vcenter_ip10.40.0.10Address the syslog datagrams come from (log.source.address)
datacenterDC-EastDatacenter name in VM and permission messages
sso_domainVSPHERE.LOCALSSO domain of all accounts and principals
collector_namelog-collector-01.lab.exampleElastic Agent host (agent.name, host.hostname)
collector_ip10.40.0.50Elastic Agent host address
collector_mac00-50-56-A1-7B-10Elastic Agent host MAC address
collector_host_id3f0b6c1e2d9a4c7f8e5b1a2d3c4e5f60Elastic Agent host id
agent_id5096d7cc-1e4b-4959-abea-7355be2913a7Elastic Agent id
agent_ephemeral_idc4a1df82-7a9c-4a3e-8546-6d7cc04538e6Elastic Agent ephemeral id
agent_version8.17.0Elastic Agent version

Related Generators